1. Why do we collect information at all?
    We collect information about you for the following purposes:
    1. Customer administration. To ensure that we maintain the highest levels of Client Support when providing you with the online service you have chosen to receive.
    2. Technical administration of the web site. To ensure that the online service you have chosen to receive is delivered to you in the most effective way.
    3. Research and development. To develop new and improve existing online services, which we believe may be of interest to you.
    4. Marketing. To provide you with details of other betterregulation.com online services, which we believe may be of interest to you. By accepting our terms and conditions you agree to the use of your data for these marketing purposes, but you can ask to 'opt out' of such marketing at any time. We will not disclose your information to any other third party.
  2. What information do we collect?
    When you register at www.betterregulation.com or use our online services, you volunteer the following information:
    1. Personal data. This data includes your name, address, email address, telephone and fax numbers.
    2. Business information. This information includes the name of your employer, your job title, your employer's address, email address, telephone and fax number.
    3. Online Identifiers. This data includes your domain name and IP address, operating system, browser version, the web site you visited prior to our site and unique number identifiers that are automatically generated by our systems when you visit our site.
    4. Your personal preferences. This data includes details of the choices you made when indicating whether you wished to receive information on other products and services.
  3. Does Better Regulation Ltd disclose personal data to other parties?
    Never. Your privacy is important to us and we will never disclose your personal data to any other company or organisation unless required to do so by law.
  4. How do we collect information?
    We collect information about you in a number of ways:
    1. Automatic programming. When you register at www.betterregulation.com and move from page to page within our site, the information you provide is automatically stored in our electronic files.
    2. Cookies. A cookie is a very small text file placed on your hard drive by a web page server. It works like an identification card whose purpose is to tell the server that you have already been to that web page before and are now returning. A cookie cannot be executed as code or deliver viruses. It can only be read by the server that gave it to you and is unique to your computer. Cookies are useful because they save you time by remembering usernames and passwords. Cookies also enable predictive text in the location box. For example, if you begin to write betterregulation's web address, by the time you have typed in www.better, your browser location box will probably be offering you www.betterregulation.com without having to key in further characters.
    3. Telephone. If we speak to you by telephone, we will ask your permission to retain the information you provide in our client database (electronic files).
    4. Research. We may find out information about you through research. For example, you may have consented to have some of your details appear in literature and directories or on the web site of your employers in order to promote their goods and services.
  5. Data Security & Operational Resilience
    1. Data Security & Operational Resilience: We implement robust cybersecurity and operational resilience measures to protect the personal data we process. Our ICT risk management framework includes continuous monitoring, encryption, and incident response procedures to prevent unauthorised access, loss, or misuse of personal data.
    2. Data Breach Notification: In the event of a data breach or ICT-related incident that compromises personal data, we will notify affected individuals and relevant authorities as required by DORA and GDPR. Our reporting framework ensures timely and transparent communication to mitigate risks.
    3. Third-Party Service Providers: We only engage third-party service providers that meet strict security and compliance standards. Under DORA, we ensure that all ICT third-party providers adhere to contractual obligations that maintain the confidentiality, availability, and integrity of personal data.
    4. Cross-Border Data Transfers & DORA Compliance: For clients operating in the EU financial sector, we ensure that our cross-border data transfers comply with both DORA and GDPR. Where applicable, we apply Standard Contractual Clauses (SCCs) and other safeguards to ensure data protection.
  6. Can you access the personal data we hold about you?
    You can ask us whether we are keeping personal data about you by contacting us at info@betterregulation.com. We will provide you with a readable copy of the personal data, which we keep about you within 14 days; however, we may require proof of your identity and apply an administration charge before disclosing your personal data to you.
    We allow you to challenge the data that we hold about you and, you may have the data rectified, amended or deleted.
  7. Privacy compliance
    Our privacy policy is compliant with the Data Protection Acts in Ireland, the UK Data Protection Act 1998, Digital Operational Resilience Act and the UK and EU GDPR.